Home · Security

Security and data sovereignty

Your collection. Your data.

Digital twins are institutional assets. The rules are simple and they never change: the institution owns every right to its data, access is private by default, and everything can leave the platform in open formats whenever you decide.

The HUB runs on SweetHive, an infrastructure built for regulated, high-trust environments. The answer to the question every institution asks first, where does the data go, is structural, not a promise.

The institution owns everything

Every scan, model and derivative belongs to the collection's owner. We operate the platform; we acquire no rights, ever.

Private by default

Access follows roles: conservators, curators and partners see only what they should. Nothing becomes public without an explicit decision, and sensitive works can stay visible to a restricted circle only.

Hosted in your country

European collections on EU infrastructure, US collections on US infrastructure: every country can have its own hosting, encrypted in transit and at rest, with residency guaranteed per region.

Provable integrity

Each file's fingerprint is notarized on a public blockchain at capture: provenance and integrity you can show an insurer or a court.

Sovereignty when required

Storage and processing can be pinned to the institution's own hardware, inside its own perimeter: the computing comes to the data, the data never leaves.

Governments and regulation

Dedicated deployments for public bodies: sovereign hosting, custom retention, and compliance with national heritage systems from day one. The connector layer →

Heavy computing should not be a privilege. The HUB routes every workload across three tiers, by sensitivity, latency and cost:

Private nodes

Sensitive, confidential work runs on machines inside the institution. Scope is enforced down to the hardware.

Edge and DePIN network

Non-sensitive heavy work, meshes, tiles, renders, bursts to a distributed network of independent nodes. Capacity grows with the network and unit costs keep falling: high-end computing stays accessible to small museums too.

You set the policy

Per workload: private only, network allowed, or automatic. The default keeps sensitive work at home. The full security model →

Export and open formats

Open formats and export always available: the twins can leave the HUB at any time, complete and readable. No lock-in by design.

FAQ

Plain answers on data and control.

Who owns the data?

The institution, always. Every scan, model and derivative belongs to the museum or to the owner of the artwork. AerariumChain operates the infrastructure and never acquires rights over the collection.

Where is the data stored?

In the region the institution chooses: EU collections on EU infrastructure, US collections on US infrastructure, and every country can have its own hosting. Data is encrypted in transit and at rest, and institutions with stricter requirements can pin storage and processing to their own hardware.

Can part of the collection stay confidential?

Yes. Everything is private by default: people see only what their role allows, and nothing is published without an explicit decision. Sensitive works can remain visible to a restricted group only.

Can we leave and take everything with us?

Yes. Full export in open formats, METS packages, meshes, TIFF pyramids, is always available. No lock-in, by contract and by design.

How do you work with governments and regulated bodies?

With dedicated deployments: sovereign or on-premise hosting, custom retention policies and compliance with national heritage regulations.

How do you prove a file has not been altered?

Every file's fingerprint is written to a public blockchain the moment it is captured. Integrity and provenance can be verified at any time, by anyone you authorize.

Detailed security documentation is available to institutions on request.